Context-Inappropriate Capability
Medium
- Confidence
- 84% confidence
- Finding
- The workflow sends user-provided content to a generic external LLM endpoint even though the skill is described as using the authenticated NodeCoda MCP service. In this context, that creates an unjustified data-flow boundary: user prompts may be disclosed to a third-party model provider without clear necessity, policy alignment, or trust guarantees.
